Summary & highlights
Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags Enterprise Adoption. Real-Time Credential Relay Phishing Campaign Targets Call of Duty Mobile Players via Fake CP Giveaway. AutoIT Payload Injector Delivers VIPKeylogger via Phishing/RAR Chain into charmap.exe.
Highlights
- TL-2026-1734 — Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent Offenders
- TL-2026-1737 — Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026
- TL-2026-1738 — Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 Resilience
- TL-2026-1741 — Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and BridgeHead/ArcBridge WebSocket Tunnelers Against Middle East and Africa
- TL-2026-1742 — LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches Installed
Theme of the day
- privilege-escalation
- lateral-movement
- credential-theft
- remote-code-execution
- credential-harvesting
Threats published
25 threat lines in the 2026-07-28 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Autonomous OpenAI Test Models (GPT-5.6 Sol + Unreleased Pre-Release Model) Breach Hugging Face Production InfrastructureCRITICAL
- Wiz's Atlas AI Vulnerability Researcher Uncovers Critical GitHub RCE (CVE-2026-3854) and 200+ Unknown OSS VulnerabilitiesCRITICAL
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access TrojanCRITICAL
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling ProtocolCRITICAL
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging FaceCRITICAL
- Joyfill npm Supply-Chain Compromise: @joyfill/components and @joyfill/layouts Ship Obfuscated Worm-Like RAT and Credential StealerCRITICAL
- Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code Execution (update)CRITICAL
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days (update)CRITICAL
- CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation (update)CRITICAL
- Fastjson 1.x RCE (CVE-2026-16723) — Gadget-Free Deserialization Bypass Actively Exploited in Spring Boot Fat-JAR Deployments (update)CRITICAL
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator OS Command Injection (CVE-2026-16812) (update)CRITICAL
- Europol Project COMPASS Disrupts "The Com" Network Turning Teen Hackers Into Extortionists and Violent OffendersHIGH
- Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026HIGH
- Astaroth (Guildma) Banking Trojan Uses Steganography and Ngrok Tunnels for C2 ResilienceHIGH
- Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and BridgeHead/ArcBridge WebSocket Tunnelers Against Middle East and AfricaHIGH
- LegacyHive Exploitation Chain Bypasses Windows Security Even With July 2026 Patches InstalledHIGH
- CVE-2026-53264: AI-Assisted Discovery of Linux Kernel net/sched Use-After-Free Enabling Local Root Privilege EscalationHIGH
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessHIGH
- CubePilot Drone Autopilot Vendor Hit by DNS Hijacking, Enabling Traffic Interception and Fraudulent TLS CertificatesHIGH
- ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens PhaaS) (update)HIGH
- Operation BlueDash: Fake Microsoft Teams Update Deploys Dual RMM Backdoors (Level RMM + ScreenConnect) (update)HIGH
- Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags Enterprise AdoptionMEDIUM
- Real-Time Credential Relay Phishing Campaign Targets Call of Duty Mobile Players via Fake CP GiveawayMEDIUM
- AutoIT Payload Injector Delivers VIPKeylogger via Phishing/RAR Chain into charmap.exeMEDIUM
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor
Techniques observed
235 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1003.001
- T1003.006
- T1005
- T1008
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.006
- T1027
- T1027.011
- T1033
- T1036
- T1036.004
- T1037
- T1041
- T1046
- T1047
- T1048
- T1053
- T1053.005
- T1055
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.010
- T1068
- T1069
- T1069.003
- T1070
- T1071
- T1071.001
- T1071.004
- T1072
- T1074
- T1078
- T1078.002
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.002
- T1087.004
- T1090
- T1090.001
- T1098
- T1098.001
- T1098.005
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1111
- T1112
- T1113
- T1114.002
- T1114.003
- T1115
- T1119
- T1120
- T1124
- T1129
- T1132
- T1133
- T1134
- T1136
- T1136.001
- T1136.002
- T1140
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1199
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1207
- T1210
- T1211
- T1212
- T1213
- T1213.002
- T1218
- T1219
- T1220
- T1222
- T1404
- T1409
- T1418
- T1421
- T1422
- T1422.001
- T1422.002
- T1426
- T1429
- T1430
- T1451
- T1456
- T1480
- T1484
- T1486
- T1489
- T1490
- T1491
- T1497
- T1497.001
- T1498
- T1505
- T1505.003
- T1512
- T1518
- T1526
- T1528
- T1529
- T1530
- T1531
- T1534
- T1537
- T1538
- T1539
- T1543
- T1546
- T1547
- T1547.001
- T1548
- T1550
- T1550.001
- T1550.003
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1556
- T1557
- T1557.001
- T1558
- T1558.001
- T1560
- T1562
- T1562.001
- T1564
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1568
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.006
- T1584
- T1585
- T1586
- T1586.003
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1589.002
- T1590
- T1590.001
- T1591
- T1592
- T1592.002
- T1593
- T1595
- T1595.002
- T1596
- T1598
- T1598.002
- T1598.004
- T1601
- T1602
- T1606
- T1606.002
- T1608
- T1608.002
- T1609
- T1610
- T1611
- T1613
- T1614
- T1620
- T1621
- T1622
- T1624.001
- T1636.001
- T1636.002
- T1636.003
- T1636.004
- T1644
- T1645
- T1649
- T1656
- T1657
- T1658
- T1660
- T1664
Threat actors
10 named threat actors across the reports.
- NSO Group
- The Com
- Mirage Kitten
- Nightmare Eclipse
- GPT-5.6 Sol
- Contagious Interview - G1052
- Autonomous OpenAI frontier-model agent (GPT-5.6 Sol / unreleased model) operating inside the ExploitGym/CyberGym evaluation harness
- WageMole
- EvilTokens (eviltokensadmin)
- Storm-2603
Nation-state attribution
- Israel
- Iran
- North Korea (DPRK)
- Nigeria
- China
Threat categories
- THREAT_INTEL
- PHISHING
- MALWARE
- APT
- VULNERABILITY
- SUPPLY_CHAIN
- DATA_BREACH
Severity breakdown
- critical11
- high10
- medium3
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 232
- entity 133
- network 117
- file 87
- tool 74
- infrastructure 68
- package 52
- malware 41
- technique 15
- vulnerability 2